Notice at collection
ANDYL may collect identifiers and contact information, account and authentication information, internet or network activity, communications, organization and authorization records, public open-source activity, and contributor-agreement information. We collect these categories directly from you, automatically from your browser or device, from an organization that authorizes your access, and from services you use to authenticate or interact with us.
We use this information to operate and secure our Sites, authenticate users, provide public registry and open-source community functions, administer contributor agreements, communicate with you, understand aggregate Site use, and meet legal obligations. Retention depends on the purpose and is described below and in the CLA Privacy Supplement.
Scope
Andyl, Inc., a Delaware corporation (ANDYL, we, us, or our), controls the personal information described in this notice. This notice applies to andyl.com, andyl.org, aos.andyl.org, related ANDYL-operated APIs, and other ANDYL-controlled websites or community services that link to it (collectively, the Sites).
The contributor-agreement service at cla.andyl.org is also covered by a more specific CLA Privacy Supplement. That supplement controls if its terms differ from this notice for contributor-agreement information.
Third-party platforms and websites have their own privacy practices. For example, GitHub governs information it collects through github.com, and a recruiting provider governs information submitted through its application service. This notice covers information ANDYL receives from those services, not their independent processing.
Information we collect
Information you provide
- Communications: your name, email address, organization, message, and other information you send by email, a contact form, an issue, or another channel.
- AOS Hub accounts: email address, password verifier, passkey credential and public-key information, identity-provider information, organization membership, invitations, permissions, and account preferences. ANDYL does not receive biometric information used locally by your device to unlock a passkey.
- Registry and service activity:package and artifact metadata, publication records, access policies, tokens, organization actions, and other content or instructions you submit through AOS Hub or its APIs.
- Contributor information: information submitted to accept or administer a contributor agreement, as detailed in the CLA Privacy Supplement.
Information collected automatically
- Request and device information: IP address, browser and operating-system information, device type, requested URL, referrer, timestamps, request headers, response status, and similar hosting, security, and diagnostic information.
- Authentication and security events:session identifiers, sign-in and token events, authentication method, authorization decisions, rate-limit signals, and abuse-prevention data. Passwords and raw session secrets are not stored as readable account records.
- Website analytics: page URL, dynamic route, filtered query parameters, referrer, approximate city or region, device type, browser, operating system, and event time on andyl.com.
Information from other sources
We may receive an account identifier, username, email address, profile information, or authentication result from GitHub, Google, or another identity provider you choose to use. An organization administrator may provide your email, membership, role, or authorization. We also receive public contribution and interaction data from GitHub, including commits, issues, pull requests, comments, public profile information, and the email address or signature included in a public commit.
How we use information
We use personal information to:
- provide, maintain, and improve the Sites and their public or account-based features;
- authenticate users, maintain sessions, issue credentials, and enforce permissions;
- operate public registries and preserve the integrity and provenance of published artifacts;
- administer open-source projects, contributions, contributor authorization, and legal evidence;
- respond to questions, requests, security reports, and other communications;
- monitor aggregate Site use, diagnose errors, prevent abuse, and protect users and systems;
- establish, exercise, or defend legal claims and enforce applicable terms; and
- comply with law, lawful requests, and regulatory obligations.
Where European data-protection law applies, our legal bases are performance of a contract or steps requested before entering one; our legitimate interests in operating secure Sites, administering open-source projects, communicating, and protecting legal rights; compliance with legal obligations; and consent where we specifically request it. You may withdraw consent at any time, but withdrawal does not affect earlier lawful processing.
Cookies, browser storage, and analytics
andyl.com uses Vercel Web Analytics to measure aggregate page use. According to Vercel, the service does not use third-party cookies, does not associate analytics events with an individual or IP address, and discards its visitor identifier after 24 hours. You can review Vercel’s analytics privacy documentation.
Account and contributor services use cookies that are necessary for sign-in, security, OAuth state, invitations, and sessions. They may also use temporary browser storage to preserve an in-progress operation across a retry. These technologies are not used for advertising. Blocking required cookies or browser storage may prevent authentication or other requested features from working.
The Sites do not currently use interest-based advertising, advertising pixels, or session-replay technology. If that changes, we will update this notice and provide any controls required by applicable law before deploying the technology.
Retention
We retain information for the shortest period reasonably necessary for the purposes described here, taking account of security, operational, legal, accounting, and dispute-resolution needs.
- Account, membership, authentication, and authorization information is retained while needed to provide and secure the account and for a reasonable period afterward.
- Sessions, magic links, challenges, and access credentials expire or are revoked according to their configuration. Security and audit events may be kept longer to investigate abuse and protect systems.
- Public repositories, registry metadata, release history, contribution records, and other public records may be retained indefinitely to preserve project history, provenance, security, and license compliance. Copies may remain in forks, mirrors, caches, and third-party archives outside our control.
- Communications are retained while needed to respond and for reasonable follow-up, legal, or security purposes.
- Contributor-agreement and contact-form retention is described in the CLA Privacy Supplement.
When information is no longer needed, we delete it, anonymize it, or isolate it from further use. Residual copies may remain temporarily in backups or where deletion is restricted by law, security needs, or an immutable legal record.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information. No system or transmission is completely secure, and we cannot guarantee absolute security. If you believe information or an account has been compromised, contact security@andyl.com.
International processing
ANDYL is based in the United States. We and our providers may process information in the United States and other countries whose laws may differ from those where you live. Where applicable law requires a transfer mechanism, we use an approved legal mechanism or another permitted basis for the transfer. Contact us for information about a mechanism applicable to your information.
Your rights and choices
Depending on where you live and whether the relevant law applies to ANDYL, you may have rights to request information about our processing; access, correct, delete, or obtain a portable copy of personal information; restrict or object to processing; withdraw consent; or appeal our response to a request. These rights are subject to exceptions, including where information must be retained to preserve a public record, administer an agreement, protect security, comply with law, or establish or defend legal claims.
You may use an authorized agent where permitted by law. We may ask for information reasonably necessary to verify identity, authority, residency, or the scope of a request. If we deny a request, you may appeal by replying to our decision and identifying the basis for the appeal.
We do not sell personal information or process it for targeted advertising or legally significant profiling. Because we do not engage in those practices, there is currently no sale or targeted-advertising opt-out to exercise. We will recognize legally required browser-based opt-out signals if our practices change.
Individuals in the European Economic Area or United Kingdom may also lodge a complaint with the data-protection authority where they live or work. We encourage you to contact us first so we can try to address the concern.
Children
The Sites are not directed to children under 13, and we do not knowingly collect personal information from them. Accounts, contributor agreements, and features that create legal obligations are intended only for people who are at least 18 or the age of legal majority where they live. Contact us if you believe a child provided personal information contrary to this notice.
Changes to this notice
We may update this notice as our Sites and practices change. We will post the revised notice, update the effective date, and provide additional notice when appropriate. Material changes apply prospectively. Previous versions are available by contacting us.
Contact
To ask a privacy question or exercise an applicable right, email privacy@andyl.com. Please describe your request and the Site or account involved. You may also contact Andyl, Inc. through the contact method published on the relevant Site.